Earlier quoted context omitted.
I happen to know first hand that the thread is not going quite to dang's liking at the moment. I'm hoping it improves, but people are having a hard time sticking to the technical and security aspects.
[flagged]
U.S. national-security leaders included me in a group chat
501–510 of 1001 posts
Re: U.S. national-security leaders included me in a group chat
#502Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…
I don't use Signal, and am unfamiliar with the UI/UX. However, it seems more plausible to me that Jeffrey Goldberg is in someone's contact list from previous on-purpose leaks (to control narrative, etc, typical "anonymous sources say" stuff) - and was accidentally added to this group.
Re: U.S. national-security leaders included me in a group chat
#503Earlier quoted context omitted.
Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…
[flagged]
One possible explanation is that it happens all the time.
Re: U.S. national-security leaders included me in a group chat
#504Earlier quoted context omitted.
He knew the system well and seemed to do enough local testing to avoid major breakage but still. Why have a bunch of rules and policies that you do not follow yourself? Because these rules and policies are for people that are judged to need them by the person with the authority and responsibility for making the decision. Policies like these always have a cost and (hopefully) a benefit. Presumably this lead dev judged…
One of the main purposes of code review is to ensure that your code is understandable to other people. Good lead developers understand this. Bad ones find a way to push through their changes without review or get them rubber stamped, in my experience. Then you end up with big parts of the codebase that only the lead dev can work in productively.
Re: U.S. national-security leaders included me in a group chat
#505Earlier quoted context omitted.
I happen to know first hand that the thread is not going quite to dang's liking at the moment. I'm hoping it improves, but people are having a hard time sticking to the technical and security aspects.
[flagged]
Re: U.S. national-security leaders included me in a group chat
#506Earlier quoted context omitted.
Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…
[flagged]
Re: U.S. national-security leaders included me in a group chat
#507If anything, I'm a bit surprised that Jeff Goldberg burned this source. If anything, I'd suspect that he'd keep the channel open as long as he could. Or, he's got other channels that work better. All the same, I mean, wow. These guys are just morons here, there's really no other way around it. I'm trying to think of a charitable way to spin this and I've got nothing. Like, very clearly, these people are going to get…
"If anything, I'd suspect that he'd keep the channel open as long as he could." The real story is that he was added to the channel, so it doesn't surprise me that he didn't try to lurk indefinitely. I'm guessing these things are also ad-hoc, so perhaps the well was already dry after the attack? But this is some truly amateur-hour shit. I've seen better communications discipline from volunteer open source projects tha…
Because those people are likely competent. The problem with hiring mostly yes-men/women is competence is secondary.
Re: U.S. national-security leaders included me in a group chat
#508In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…
I'd go with b: They've been talking for a while about finding information leaks, and the messages themselves seem a bit staged. They probably did it intentionally with different people, with slightly different wording, and because of which version got published they just identified a leak.
Like, do you think they did the same thing with multiple journalists in an attempt to see who would publish and who would keep their mouths shut?
Bear in mind, when you join a Signal group you don't see the conversation history from before you arrived, only the live updates that take place during the time you're a member. Also, anyone in the group can view the list of group members and receives notifications about people being added to/removed from/leaving the group.
Re: U.S. national-security leaders included me in a group chat
#509In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…
It was Mike Waltz who invited Jeff Goldberg to connect on Signal. It seems inordinately unlikely that he would have been uninvolved if it was an intentional leak.
Re: U.S. national-security leaders included me in a group chat
#510I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…
At least here in the UK our politicians delete all their messages on WhatsApp https://www.politico.eu/article/the-british-governments-disa... More seriously, having worked in an undisclosed defence company, we were told that we would be prosecuted if we did this. There were many many security controls in place that prevented this from happening on top of the threat.